Threat Database Backdoors Backdoor.Spy.Agent.QE

Backdoor.Spy.Agent.QE

By CagedTech in Backdoors

Threat Scorecard

Popularity Rank: 23,477
Threat Level: 60 % (Medium)
Infected Computers: 122
First Seen: May 17, 2023
Last Seen: June 7, 2026
OS(es) Affected: Windows

The detection of Backdoor.Spy.Agent.QE on your system indicates a potentially serious security threat. This backdoor threat can compromise your system's security and allow unauthorized access to your data. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Backdoor.Spy.Agent.QE?

Backdoor.Spy.Agent.QE is a type of malware that allows unauthorized access to your system. The term "backdoor" refers to a method of bypassing normal security mechanisms to gain access to a system. This type of malware can be used to spy on your activities, steal sensitive information, or take control of your system. The "Spy" component of the name suggests that this malware is designed to gather intelligence or monitor your activities.

How Backdoor.Spy.Agent.QE Operates

Backdoor.Spy.Agent.QE operates by creating a covert channel of communication between your system and a remote server. This allows the attackers to send commands to your system, receive stolen data, or upload additional malware. The malware may use various techniques to evade detection, such as encrypting its communication or disguising itself as a legitimate program. Once installed, the malware can remain dormant until it is activated by the attackers, making it challenging to detect.

Symptoms of Infection

The symptoms of a Backdoor.Spy.Agent.QE infection can be subtle, but they may include unusual system behavior, such as slow performance, unexpected crashes, or unfamiliar programs running in the background. You may also notice suspicious network activity, such as unusual outgoing connections or data transfers. In some cases, the malware may attempt to hide its presence by disabling security software or preventing you from accessing certain system features.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar programs or icons
  • Increased system crashes or instability
  • Unusual network activity or data transfers

How to Remove Backdoor.Spy.Agent.QE

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow you to download removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Backdoor.Spy.Agent.QE from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above, you can help to ensure that your system is clean and secure. It is essential to remain vigilant and to continue monitoring your system for any signs of malware activity. Remember to always use reputable security software and to keep your operating system and applications up to date to prevent future infections.

Analysis Report

General information

Family Name: Backdoor.Spy.Agent.QE
Signature status: No Signature

Known Samples

MD5: 941fc5723e659f2cb1ec31143db8afd1
SHA1: 8e39f50457623cc7722a8c04868b8dddee3bf730
SHA256: B1C6EDE43B4144ADA268F9A05CC35F68CCFA08561C8D0A6CC6BE2B9D1B9A5132
File Size: 328.70 KB, 328704 bytes
MD5: c0c27a980406fc23dcc6105a324a649b
SHA1: a0d40ae8dde3820398c9ce3c4d1c8beac9d8f3ab
SHA256: 798A8713DD5974ED9A5D6221A7E4E9FA7D7F98BA3684471737ADD1181D89E1D9
File Size: 2.08 MB, 2084864 bytes
MD5: 1871ed4f8fe283e8a7d1d467ec500a2a
SHA1: f222a32e0ea742c41634967028769ebde9ce5f38
SHA256: 2F5301DA57470241777CA13FFB31A4A8C91BA7E8CF3E8AFC69B230C32EADB508
File Size: 199.17 KB, 199168 bytes
MD5: f35e814b33572a89cf185fd015e84c82
SHA1: 85f72ccda9d92de598e062b6573605e509ed7812
SHA256: 26000DBC42937B8BD74E2FDD98260B3F776E4913840EFA05CA02BEBE185D4D13
File Size: 213.50 KB, 213504 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • LunaTranslator shareddllproxy v5.33
  • LunaTranslator v7.11
  • LunaTranslator v10.5
Company Name 156608225
File Description
  • Lucy 快速启动
  • LunaTranslator
  • LunaTranslator shareddllproxy
File Version
  • 10.5.9.8
  • 7.11.4.0
  • 5.33.0.0
  • 1.8.0.0
Internal Name
  • Lucy
  • LunaTranslator
  • LunaTranslator shareddllproxy
Legal Copyright
  • Copyright 2023
  • HIllya51 (C) 2024
  • HIllya51 (C) 2025
Original Filename
  • Lucy.exe
  • LunaTranslator
  • LunaTranslator shareddllproxy
Product Name
  • Lucy 快速启动
  • LunaTranslator
  • LunaTranslator shareddllproxy
Product Version
  • 10.5.9.8
  • 7.11.4.0
  • 5.33.0.0
  • 1.8.0.0

File Traits

  • HighEntropy
  • imgui
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 717
Potentially Malicious Blocks: 108
Whitelisted Blocks: 604
Unknown Blocks: 5

Visual Map

0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x x x x 0 x x x 0 0 x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? x ? 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x 0 x x x x x x x 0 0 x x x x 0 0 0 x ? x x x x x x x x x x 0 0 0 0 0 0 0 x 0 x x x 0 x 0 0 0 x 0 x x x x 0 x 0 0 0 x x x 0 0 x x 0 0 x x 0 0 0 0 0 0 x 0 x x x x x x 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 3 1 0 0 0 0 0 2 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x x x 0 x x 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 x x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 1 0 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Process Shell Execute
  • ShellExecute

Shell Command Execution

runas c:\users\user\downloads\a0d40ae8dde3820398c9ce3c4d1c8beac9d8f3ab_0002084864 main

Related Posts

Trending

Most Viewed

Loading...